Breaking Down Mustang Panda’s Windows Endpoint Campaign
ID: 9cb9f6b7-db3c-5a14-9caf-f7c5710fa24c
STIX ID: report--9cb9f6b7-db3c-5a14-9caf-f7c5710fa24c
Feed Name: Resources-2
Date Published: 2025-08-26
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
Mustang Panda is a persistent, sophisticated espionage-focused APT that has conducted global campaigns since 2012 against think tanks, diplomatic entities, telecoms and government organizations; the report documents its tooling (PlugX, ToneShell, LOTUSLITE, SnakeDisk USB worm), initial access vectors (spearphishing, Azure-hosted lures, USB propagation), defense-evasion/persistence techniques (DLL side‑loading, kernel rootkit, registry modifications, geofencing), and C2 obfuscation methods (Cloudflare proxying, TLS header spoofing, Googlebot/Microsoft headers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
